Epsilon Framework Themes (Various Versions) - Unauthenticated Plugin Activation/Deactivation

2020-10-01 00:00
Jerome Bruandet

Strategic Overview

Status
Patched in 1.3.2
Affected ThemeNewspaper X
Affected Version<= 1.3.1
CVSS6.5Medium
CVECVE-2020-36721
View all Newspaper X vulnerabilities

Vulnerability Overview

The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.

Technical Analysis

REMEDIATION: Update to version 1.3.2, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C